REMARK^^^ 

The Examiner is thanked for granting a telephone interview with Applicant' s 
representative during which amendments to claims 1 and 1 1 were discussed. The Examiner 
suggested further clarification of the use of "statistical results" as recited in the claims. 
Accordingly, Applicant has made amendments further clarifying this term. 

Claims 1-30 are rejected under 35 U.S.C. 103(a) as being unpatentable over Sururonen et 
al (Publ. No. 2003/0145228) in view of Douglas et al. (U.S. Pat. No. 6,269,400), further in view 
of White et al (IBM Research White Paper, 1999), and further in view of Cass ("Anatomy of 
Malice," Spectrum IEEE, Nov. 2001). 

Claims 1 and 1 1 have been amended to recite that the statistical results of abnormal 
events are used to determine what actions the virus monitor should take to address the potential 
threat from the vims. The abnoiTnal events are defined in policies and detection mles stored in 
the virus monitor. Support for the amendments can be found, for example, at paragraphs 0021 
and 0040 in the specification. Applicant asserts that none of the cited references teach, describe, 
or suggest these claimed features either alone or in combination. 

Claim 21 has been amended to reflect the steps of method claim 11 as a computer 
program product and also includes that the statistical results of abnormal events are used to 
determine what actions the virus monitor should take to address the potential threat from the 
virus. 

The Cass reference is used to suggest or show in combination with the other references 
the following claim limitation (taken from claim 11, including current amendments): 

"creating a detection module that detects whether a client device is infected with a virus 
and triggers the introduction of an anti- virus infection module so that the virus in the client 
device is overwritten and an anti- virus agent payload is created based on features of the selected 
computer virus and which performs as a cleaning/repairing payload capable of cleaning and 
repairing damage done to the client device." 
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However, Applicant was not able to find several elements in this limitation in the Cass 
reference. After reading the entire reference carefully. Applicant believes that Cass does not 
show or suggest alone or in combination with the other references, a detection module that 
triggers the introduction of an anti-virus so that the virus in the client device is overwritten. Nor 
does the Cass reference show or suggest alone or in combination with the other references an 
anti-virus agent pay load created based on features of the virus and which performs as a 
cleaning/repairing pay load for the client device.'' Applicant could not find any reference to 
these claimed limitations in the Cass reference. Finally, the Office Action states on page 8 at the 
end of the middle paragraph, that "the payload also capable of inoculating the client device 
against the virus in cases where the client device was not infected by the computer virus," and 
cites "Source of Mischief section, page 59 of Cass article. However, neither claim 1 or 11 
recites any limitations regarding inoculation or, more specifically, that the payload performs the 
inoculation of the client device. Regardless, Applicant could not find any teaching or showing of 
inoculation of uninfected client devices in the Cass reference. 



Applicant believes that all pending claims are allowable and respectfully requests a 

Notice of Allowance for this application from the Examiner. Should the Examiner believe that a 

telephone conference would expedite the prosecution of this application, the undersigned can be 

reached at the telephone number set out below. 

Respectfully submitted, 
BEYER WEAVER LLP 

/Rupak Nag/ 

Rupak Nag 
Reg. No. 37,493 

P.O. Box 70250 

Oakland, CA 94612-0250 
Telephone: (612) 252-3335 
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